Privacy Policy
← Back to app

Last updated: 8 July 2026 · Contact: support@eventpassreader.com

What Event Pass Reader is
Event Pass Reader ("we") is a check-in tool for event organisers. Organisers upload their guest lists and scan tickets at the door. For the guest data an organiser uploads, the organiser decides what is collected and why — they are the data controller; we only store and process it to run the service on their behalf, as their data processor. This is set out in our Data Processing Agreement. For an organiser's own account and billing details, we are the controller.
What we store
  • Organiser accounts: your email address and a hashed password. If you buy a paid plan, our payment processor (Stripe) handles the payment; we keep only a customer reference and your plan status, never your full card details.
  • Guest lists uploaded by organisers: guest name, email address (optional), ticket type, and the ticket's pass code.
  • Check-in records: the time of each scan, the door name, an anonymous device identifier, and the name of the staff member who scanned (if entered) — kept as an audit log (including undone check-ins, which are marked revoked).
  • Door staff: if you invite people to help scan, we store their email address to give them access, and their name appears on the check-in records they create.
Where it lives
Data is stored in a Supabase (PostgreSQL) database hosted in the EU (Ireland, eu-west-1), encrypted in transit and at rest. Supabase keeps encrypted automated backups for disaster recovery, typically for up to about 30 days, after which they are overwritten. The app is served by Vercel. Account emails (confirmations, password resets) are sent through Resend. If you buy a paid plan, payments are processed by Stripe. Scanner devices keep a local copy of the guest list so check-in works without a connection; that copy is erased when the organiser signs out.
International transfers
Guest data is stored in the EU (Ireland). Some of our providers — Vercel, Resend and Stripe — are based in the United States, so limited data (such as an organiser's account email or billing details, and the technical data needed to serve the app) may be processed outside the European Economic Area. Where that happens, the transfer is covered by the provider's GDPR terms and the European Commission's Standard Contractual Clauses.
What we don't do
We don't sell data, we don't use tracking or advertising cookies, we don't run third-party analytics or error-tracking, and guests are never emailed by us. The only browser storage used is for your login session and the offline scanning cache.
Retention and deletion
Guest data stays until the organiser deletes it. Organisers can export attendance (CSV), remove an individual guest, or erase all guest data for an event directly from the dashboard — these deletions are immediate and permanent and include the guest's check-in records. When you close your account or delete an event, we delete its guest data from our live systems within 30 days (you can export a copy first); any residual copies in encrypted backups are purged within the backup cycle described above.
Your rights (GDPR)
If you attended an event and want your data accessed, corrected, or erased, contact your event's organiser — they control their guest list and have the tools to do it immediately. For your own account data, or if you can't reach the organiser, contact us at the address above. You can also complain to your local data protection authority; in Spain this is the AEPD (Agencia Española de Protección de Datos).

This policy is provided in several languages for convenience; the English version is authoritative.